Data Gateway System for Secure Cloud Intercommunication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for data intercommunication between private and public cloud environments face challenges such as high costs, complex structures, difficulty in maintenance, and security concerns, particularly with VPN connections and specific interface methods, which also raise compliance issues with data storage.

Innovation Solution

A data gateway system comprising a client system in a private cloud environment and a cloud server in a public cloud environment, utilizing a connector module and an authentication management module to establish a secure connection through a gateway code, enabling high-security data intercommunication without the need for physical connections or local databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If VPN connection method is used for data transmission between internal network and public network, then data intercommunication is achieved, but cost increases and structure becomes complex

Engineering Contradiction:
Improvedata intercommunication capabilityVSAvoidconnection structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a data gateway as an intermediary component that mediates between the private cloud environment and public cloud environment. The gateway includes a connector module that establishes connections and an authentication management module that verifies permissions, enabling data intercommunication without requiring complex VPN configurations or physical connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional mechanical connection methods (VPN, physical interfaces) with a software-based gateway system. The gateway uses authentication tokens and code-based connection mechanisms instead of complex network tunneling configurations, simplifying the overall system structure while maintaining data intercommunication capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If specific interface method is used to establish connection to internal network, then connection is achieved, but security deteriorates

Engineering Contradiction:
Improveconnection capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication before allowing any data transmission. The authentication management module verifies the client system's permission and issues an authentication token in advance. This preliminary security check ensures that only authorized systems can establish connections, preventing unauthorized access while maintaining connection capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The data gateway acts as a secure intermediary between the private and public cloud environments. It includes an authentication management module that verifies permissions and a connector module that manages secure connections. This intermediary structure maintains security by controlling and monitoring all data exchanges, preventing direct unauthorized access to the internal network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If conventional connection methods are used, then data transmission is achieved, but maintenance difficulty increases

Engineering Contradiction:
Improvedata transmission functionVSAvoidmaintenance difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of repair

Solution Approach 1:

The patent implements self-service capabilities where the gateway automatically manages connection establishment, authentication, and data transmission. The connector module automatically establishes connections based on authentication tokens, and the system self-manages connection states without requiring manual intervention or complex maintenance procedures, significantly easing maintenance difficulties.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If traditional gateway systems are deployed, then data intercommunication is enabled, but hardware resources and local databases are required

Engineering Contradiction:
Improvedata intercommunication functionVSAvoidhardware resources requirement
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent replaces traditional hardware-based gateway systems with a software-based implementation. The data gateway functions as a software application that can be deployed without extensive hardware resources or local databases. The authentication management and connection management are performed through software modules that process data in-memory, eliminating the need for complex hardware infrastructure while maintaining full data intercommunication functionality.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12015608B2Data gateway system and data intercommunication method
Publication Date: 2024.06.18 DIGIWIN SOFTWARE CO LTD
  • US12015608B2 patent drawing
  • US12015608B2 patent drawing
  • US12015608B2 patent drawing

AI summary

A data gateway system and a data intercommunication method are provided. The data gateway system includes a client system and a cloud server. The client system includes a first connector module and a listener module. The cloud server includes a second connector module and an authentication management module. The listener module performs a command listening for the cloud server. When the listener module obtains a connection configuration information, the client system sends a connection request command to the cloud server through the first connector module, so that the cloud server receives the connection request command through the second connector module, and issues a gateway code. The cloud server sends the gateway code to the first connector module of the client system through the second connector module, so that the client system establishes a connection between the client system and the cloud server based on the gateway code.